Mozilla

Firefox

2918 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 01.10.2024 16:15:10
  • Zuletzt bearbeitet 03.11.2025 23:17:33

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site I...

  • EPSS 0.11%
  • Veröffentlicht 01.10.2024 16:15:10
  • Zuletzt bearbeitet 03.11.2025 23:17:34

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Sit...

  • EPSS 0.29%
  • Veröffentlicht 01.10.2024 16:15:10
  • Zuletzt bearbeitet 04.04.2025 14:39:09

A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affec...

  • EPSS 0.15%
  • Veröffentlicht 01.10.2024 16:15:10
  • Zuletzt bearbeitet 04.04.2025 14:39:01

It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thun...

  • EPSS 0.19%
  • Veröffentlicht 01.10.2024 16:15:10
  • Zuletzt bearbeitet 18.03.2025 16:15:26

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

  • EPSS 0.6%
  • Veröffentlicht 01.10.2024 16:15:10
  • Zuletzt bearbeitet 18.03.2025 20:15:25

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128....

  • EPSS 0.26%
  • Veröffentlicht 01.10.2024 16:15:10
  • Zuletzt bearbeitet 14.03.2025 16:15:39

A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < ...

  • EPSS 0.22%
  • Veröffentlicht 17.09.2024 19:15:29
  • Zuletzt bearbeitet 18.03.2025 21:15:32

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.

  • EPSS 10.37%
  • Veröffentlicht 17.09.2024 13:15:04
  • Zuletzt bearbeitet 19.03.2025 16:15:30

Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as th...

  • EPSS 0.28%
  • Veröffentlicht 06.09.2024 19:15:12
  • Zuletzt bearbeitet 04.04.2025 14:38:20

An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbir...